Lucene search

K
nvd[email protected]NVD:CVE-2015-1814
HistoryOct 16, 2015 - 8:59 p.m.

CVE-2015-1814

2015-10-1620:59:11
CWE-264
web.nvd.nist.gov

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.005 Low

EPSS

Percentile

77.4%

The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a “forced API token change” involving anonymous users.

Affected configurations

NVD
Node
jenkinsjenkinsMatch1.596.1lts
Node
redhatopenshiftRange3.1enterprise
Node
jenkinsjenkinsRange1.605

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.005 Low

EPSS

Percentile

77.4%